Juniper Advanced Threat Prevention Appliance
98
Copyright© 2018, Juniper Networks, Inc.
set honeypot (collector mode)
Parameters
Example
The following example sets an inside data path proxy:
JATP(collector)# set proxy inside 10.1.1.1 53
The following example sets an outside data path proxy:
JATP(collector)# set proxy inside 10.2.1.1
Table 5-16 set honeypot
Description
Enables and disables the SSH-Honeypot feature for a Traffic Collector.
A honeypot can be deployed within a customer network to detect network activity
generated by malware attempting to infect or attack other machines in a local area
network. These attempted SSH logins can be used to supplement detection of
lateral spread.
There are two parameters that can be set for a honeypot:
• Enable/disable a honeypot
• Set a Static IP (IP, mask, and gateway) or DHCP of a publicly addressable inter-
face
See Also:
show honeypot
command in show (collector mode)
Product(s) CLI
All-in-One | Collector
Mode(s)
collector
Syntax
(collector)# set honeypot ssh-honeypot enable dhcp
(collector)# set honeypot ssh-honeypot enable address (IP
address) netmask (subnet IP) gateway (IP address)
(collector):# set honeypot ssh-honeypot disable
Example
The following example enables the SMB parser for lateral detections:
(collector)#
set honeypot ssh-honeypot enable
address 1.2.3.4 netmask 255.255.0.0 gateway
1.2.3.1
NOTE
The static IP configuration does not require configuring DNS.
Honeypots do not require a DNS server at this time.
Table 5-15 set proxy
inside
Sets the inside proxy IP addresses
outside
Sets the outside proxy IP addresses
add
Adds a proxy configuration.
remove
Removes a proxy configuration.
Summary of Contents for Advanced Threat Prevention Appliance
Page 70: ...Juniper Advanced Threat Prevention Appliance 62 Copyright 2018 Juniper Networks Inc ...
Page 94: ...Juniper Advanced Threat Prevention Appliance 86 Copyright 2018 Juniper Networks Inc ...
Page 118: ...Juniper Advanced Threat Prevention Appliance 110 Copyright 2018 Juniper Networks Inc ...